logo

UNC3753 Used Vishing and Physical Intrusions in U.S. Data Theft Extortion Campaign

ID: a9393e87-7855-5589-9203-f578cebba587

STIX ID: report--a9393e87-7855-5589-9203-f578cebba587

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2026-06-08

Date Updated: 2026-06-08

Author: [email protected] (The Hacker News)

...
...

Google researchers attribute an ongoing, financially motivated extortion campaign to UNC3753 (aka Chatty Spider / Silent Ransom Group) that targets professional, legal, and financial services via vishing and social-engineering pretexts to induce victims to run legitimate RMM/remote‑access tools, enabling rapid file discovery and exfiltration. Stolen data (legal agreements, PII, financial records) is staged to fast‑flux domains and a public leak site, with extortion demands typically issued within hours; the actor shares overlaps with past Conti offshoot activity and has been observed using LockBit Black historically.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.